Skip to content
This repository has been archived by the owner on May 1, 2020. It is now read-only.

Bump node-sass to 4.9.3 to fix security warnings #1483

Merged
merged 1 commit into from
Oct 2, 2018

Conversation

vially
Copy link
Contributor

@vially vially commented Oct 1, 2018

This should fix the security warnings npm audit reports (related to the hoek library).

@imhoffd imhoffd merged commit 82a692e into ionic-team:master Oct 2, 2018
@imhoffd
Copy link
Contributor

imhoffd commented Oct 2, 2018

Thanks @vially!

@vially vially deleted the bump-node-sass-v4.9.3 branch October 2, 2018 17:27
@ammarhaiderbjss
Copy link

@dwieeb Has this change been published to npm? Do you need to bump the package version too?

@imhoffd
Copy link
Contributor

imhoffd commented Oct 25, 2018

@ammarhaiderbjss Sorry, not yet. I was hoping to do some work on the new environments feature first.

@vially
Copy link
Contributor Author

vially commented Nov 22, 2018

Instead of waiting for the new features (which might take some time to implement), could a new release be published which includes this patch (or maybe even #1493 if possible)?

Lots of people seem to be affected by this vulnerability and I think it's a good idea to get a new release out as soon as possible.

@Enrico204
Copy link

I agree with @vially : if new features are not ready yet, just release a bugfix version (as these bugfixes are actually security fixes)

trsrm added a commit to powwowinc/ionic-app-scripts-tiny that referenced this pull request Jan 2, 2019
3.1.9:
* fix(2889): fix build error with --prod
* fix(serve): start listening when watch is ready
* fix(live-server): update android platform path (ionic-team#1407)
* docs(changelog): 3.1.9

3.1.10:
* Update node-sass dependency (ionic-team#1435)
Updating node-sass dependency from 4.7.2 to 4.9.0 to make it works with node 10 on windows (build fail with ionic start)
* chore(package): bump deps (ionic-team#1421)
* chore(deps): no package lock
* chore(changelog): 3.1.10

3.1.11:
* fix(serve): fix EADDRINUSE issue with dev logger server
fixes ionic-team/ionic-cli#3368
fixes ionic-team/ionic-cli#1678
fixes ionic-team/ionic-cli#1830
fixes ionic-team/ionic-cli#1721
fixes ionic-team/ionic-cli#1866
fixes ionic-team/ionic-cli#1808
fixes ionic-team/ionic-cli#3022
* docs(changelog): 3.1.11 changes

3.2.0:
* feat(environments): configuration via process.env.VAR replacement (ionic-team#1471)
* fix(sass): remove PostCSS warning (ionic-team#1364)
This removes following warning:
Remove warning: Without `from` option PostCSS could generate wrong source map or do not find Browserslist config. Set it to CSS file path or to `undefined` to prevent this warning
`from: the input file name (most runners set it automatically).`
Source: https://github.com/postcss/postcss
Fixes ionic-team#1359 #13763
ionic-team#1359
ionic-team/ionic-framework#13763
* fix(serve): use wss protocol for secure websocket when page is using https (ionic-team#1358)
* docs(changelog): 3.2.0

3.2.1:
* docs(readme): add note about existing declaration
addresses ionic-team/ionic-cli#3541
* chore(deps): update webpack to 3.12.0 (ionic-team#1477)
* chore(deps): bump node-sass to 4.9.3 to fix security warnings (ionic-team#1483)
* chore(deps): bump node-sass to 4.10.0 to fix security warnings (ionic-team#1493)
* docs(changelog): 3.2.1
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants